SlideShare uma empresa Scribd logo
1 de 18
Treinamento ACL


                        Vídeo Aula 1


Rodrigo Rovere
www.ciscoredes.com.br




                                       Outubro/2012   1
www.ciscoredes.com.br




 ACL
    Lista de instrução
    Executada linha a linha
    Aplicada as camadas superiores




                                                         2
www.ciscoredes.com.br




 Como aplicar:
    Lembrar dos três Ps
       Por interface
       Por protocolo
       Por direção




                                              3
www.ciscoredes.com.br




                   4
www.ciscoredes.com.br




 Tipos de ACL:
    Padrão:
     access-list 10 permit 192.168.30.0 0.0.0.255




  Estendida:
     access-list 103 permit tcp 192.168.30.0 0.0.0.255 any eq 80




                                                                   5
www.ciscoredes.com.br




Nomeada
  CiscoRedes(config)# ip access-list extended NOMEDAACL


  CiscoRedes(config-ext-nacl)# deny tcp host 192.168.0.100 host 192.168.100.100 eq 110
  CiscoRedes(config-ext-nacl)# deny tcp host 192.168.10.100 host 192.168.100.100 eq 80
  CiscoRedes(config-ext-nacl)# permit ip any any




* Remark
  CiscoRedes(config)# access-list 1 remark ++ Permitindo o host do chefe ++




                                                                                         6
www.ciscoredes.com.br




Linhas numeradas
  CiscoRedes# show access-lists
  Standard IP access list 2
    30 permit 172.16.1.11
    20 permit 172.16.1.10
    10 permit 172.16.1.2

  CiscoRedes(config)# ip access-list standard 2
  CiscoRedes(config-std-nacl)# 25 permit 172.16.1.7
  CiscoRedes(config-std-nacl)# 15 permit 172.16.1.16




                                                                          7
www.ciscoredes.com.br




 Processo:
    Permit


   Deny


   Implícito




                                   8
www.ciscoredes.com.br




 Serviços:
   • ahp Authentication Header Protocol
   • eigrp   Cisco's EIGRP routing protocol
   • esp     Encapsulation Security Payload
   • gre     Cisco's GRE tunneling
   • icmp    Internet Control Message Protocol
   • ip      Any Internet Protocol
   • ospf    OSPF routing protocol
   • tcp     Transmission Control Protocol
   • udp     User Datagram Protocol




                                                                    9
www.ciscoredes.com.br




 Máscara Coringa ( WildCard ):
    192.168.10.16/28




    10.15.20.0/23




                                                    10
www.ciscoredes.com.br




 Portas:
    Intervalo de Número de Portas                Grupo de Portas
               de 0 a 1023                 Portas conhecidas ( comum )
             de 1024 a 49151                     Portas registradas
            de 49152 a 65535              Portas dinâmicas e/ou privadas

                               HTTP        80

                               HTTPS       443

                               POP3        110

                               SMTP        25

                               DNS         53

                               FTP         21

                               FTP-DATA    20

                                                                            11
www.ciscoredes.com.br




                  12
www.ciscoredes.com.br



ACLs adicionais no CCNA

   Reflexiva
     CiscoRedes(config)#access-list extended SURFING
     CiscoRedes(config-ext-nacl)#permit tcp 192.168.10.0 0.0.0.255 any eq 80

     CiscoRedes(config)#access-list extended BROWSING
     CiscoRedes(config-ext-nacl)#permit tcp any 192.168.10.0 0.0.0.255 established

   Dinâmicas
     CiscoRedes(config)#username Student password 0 cisco

     CiscoRedes(config)#access-list 101 permit tcp any host 10.2.2.2 eq telnet
     CiscoRedes(config)#access-list 101 dynamic testlist timeout 15 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255

     CiscoRedes(config)#interface serial 0/0
     CiscoRedes(config-if)#ip access-group 101 in

     CiscoRedes(config)#line vty 0 4
     CiscoRedes(config-line)#login local

     CiscoRedes(config-line)#autocommand access-enable host timeout 15




                                                                                                                       13
www.ciscoredes.com.br




                  14
www.ciscoredes.com.br




 Temporizada
  CiscoRedes(config)time-range tododia
  CiscoRedes(config-time-range)#periodic Monday Wednesday Friday 8:00 to 17:00

  CiscoRedes(config)#access-list 101 permit tcp 192.168.10.0 0.0.0.255 any eq telnet time-range tododia

  CiscoRedes(config)#interface serial 0/0
  CiscoRedes(config-if)#ip access-group 101 out




                                                                                                          15
www.ciscoredes.com.br




                  16
www.ciscoredes.com.br




Referências:


   http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00800a5b9a.shtml



   http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfacls.html#wp1000957




                                                                                                     17
www.ciscoredes.com.br




                  18

Mais conteúdo relacionado

Último

ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docxATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx2m Assessoria
 
Luís Kitota AWS Discovery Day Ka Solution.pdf
Luís Kitota AWS Discovery Day Ka Solution.pdfLuís Kitota AWS Discovery Day Ka Solution.pdf
Luís Kitota AWS Discovery Day Ka Solution.pdfLuisKitota
 
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docxATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx2m Assessoria
 
Programação Orientada a Objetos - 4 Pilares.pdf
Programação Orientada a Objetos - 4 Pilares.pdfProgramação Orientada a Objetos - 4 Pilares.pdf
Programação Orientada a Objetos - 4 Pilares.pdfSamaraLunas
 
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docxATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx2m Assessoria
 
Boas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsBoas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsDanilo Pinotti
 
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docxATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx2m Assessoria
 
Padrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploPadrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploDanilo Pinotti
 

Último (8)

ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docxATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
 
Luís Kitota AWS Discovery Day Ka Solution.pdf
Luís Kitota AWS Discovery Day Ka Solution.pdfLuís Kitota AWS Discovery Day Ka Solution.pdf
Luís Kitota AWS Discovery Day Ka Solution.pdf
 
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docxATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
 
Programação Orientada a Objetos - 4 Pilares.pdf
Programação Orientada a Objetos - 4 Pilares.pdfProgramação Orientada a Objetos - 4 Pilares.pdf
Programação Orientada a Objetos - 4 Pilares.pdf
 
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docxATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
 
Boas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsBoas práticas de programação com Object Calisthenics
Boas práticas de programação com Object Calisthenics
 
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docxATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
 
Padrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploPadrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemplo
 

Destaque

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 

Destaque (20)

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 

Lista de Controle ( ACL )

  • 1. Treinamento ACL Vídeo Aula 1 Rodrigo Rovere www.ciscoredes.com.br Outubro/2012 1
  • 2. www.ciscoredes.com.br  ACL  Lista de instrução  Executada linha a linha  Aplicada as camadas superiores 2
  • 3. www.ciscoredes.com.br  Como aplicar:  Lembrar dos três Ps  Por interface  Por protocolo  Por direção 3
  • 5. www.ciscoredes.com.br  Tipos de ACL:  Padrão: access-list 10 permit 192.168.30.0 0.0.0.255 Estendida: access-list 103 permit tcp 192.168.30.0 0.0.0.255 any eq 80 5
  • 6. www.ciscoredes.com.br Nomeada CiscoRedes(config)# ip access-list extended NOMEDAACL CiscoRedes(config-ext-nacl)# deny tcp host 192.168.0.100 host 192.168.100.100 eq 110 CiscoRedes(config-ext-nacl)# deny tcp host 192.168.10.100 host 192.168.100.100 eq 80 CiscoRedes(config-ext-nacl)# permit ip any any * Remark CiscoRedes(config)# access-list 1 remark ++ Permitindo o host do chefe ++ 6
  • 7. www.ciscoredes.com.br Linhas numeradas CiscoRedes# show access-lists Standard IP access list 2 30 permit 172.16.1.11 20 permit 172.16.1.10 10 permit 172.16.1.2 CiscoRedes(config)# ip access-list standard 2 CiscoRedes(config-std-nacl)# 25 permit 172.16.1.7 CiscoRedes(config-std-nacl)# 15 permit 172.16.1.16 7
  • 8. www.ciscoredes.com.br  Processo:  Permit  Deny  Implícito 8
  • 9. www.ciscoredes.com.br  Serviços: • ahp Authentication Header Protocol • eigrp Cisco's EIGRP routing protocol • esp Encapsulation Security Payload • gre Cisco's GRE tunneling • icmp Internet Control Message Protocol • ip Any Internet Protocol • ospf OSPF routing protocol • tcp Transmission Control Protocol • udp User Datagram Protocol 9
  • 10. www.ciscoredes.com.br  Máscara Coringa ( WildCard ):  192.168.10.16/28  10.15.20.0/23 10
  • 11. www.ciscoredes.com.br  Portas: Intervalo de Número de Portas Grupo de Portas de 0 a 1023 Portas conhecidas ( comum ) de 1024 a 49151 Portas registradas de 49152 a 65535 Portas dinâmicas e/ou privadas HTTP 80 HTTPS 443 POP3 110 SMTP 25 DNS 53 FTP 21 FTP-DATA 20 11
  • 13. www.ciscoredes.com.br ACLs adicionais no CCNA  Reflexiva CiscoRedes(config)#access-list extended SURFING CiscoRedes(config-ext-nacl)#permit tcp 192.168.10.0 0.0.0.255 any eq 80 CiscoRedes(config)#access-list extended BROWSING CiscoRedes(config-ext-nacl)#permit tcp any 192.168.10.0 0.0.0.255 established  Dinâmicas CiscoRedes(config)#username Student password 0 cisco CiscoRedes(config)#access-list 101 permit tcp any host 10.2.2.2 eq telnet CiscoRedes(config)#access-list 101 dynamic testlist timeout 15 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 CiscoRedes(config)#interface serial 0/0 CiscoRedes(config-if)#ip access-group 101 in CiscoRedes(config)#line vty 0 4 CiscoRedes(config-line)#login local CiscoRedes(config-line)#autocommand access-enable host timeout 15 13
  • 15. www.ciscoredes.com.br  Temporizada CiscoRedes(config)time-range tododia CiscoRedes(config-time-range)#periodic Monday Wednesday Friday 8:00 to 17:00 CiscoRedes(config)#access-list 101 permit tcp 192.168.10.0 0.0.0.255 any eq telnet time-range tododia CiscoRedes(config)#interface serial 0/0 CiscoRedes(config-if)#ip access-group 101 out 15
  • 17. www.ciscoredes.com.br Referências: http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00800a5b9a.shtml http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfacls.html#wp1000957 17